2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35642 | MEDIUM | 5.9 | 0.3% | Jun 3, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bryan Hadaw... |
| CVE-2024-35641 | MEDIUM | 5.9 | 0.3% | Jun 3, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GregRoss Ju... |
| CVE-2024-37031 | MEDIUM | 6.1 | 0.3% | Jun 3, 2024 | The Active Admin (aka activeadmin) framework before 3.2.2 for Ruby on Rails allows stored XSS in certain situations wher... |
| CVE-2024-20075 | MEDIUM | 6.7 | 0.1% | Jun 3, 2024 | In eemgpu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of... |
| CVE-2024-20074 | MEDIUM | 6.6 | 0.2% | Jun 3, 2024 | In dmc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr... |
| CVE-2024-20073 | MEDIUM | 6.6 | 0.4% | Jun 3, 2024 | In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local esca... |
| CVE-2024-20072 | MEDIUM | 6.6 | 0.4% | Jun 3, 2024 | In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escal... |
| CVE-2024-20071 | MEDIUM | 4.4 | 0.2% | Jun 3, 2024 | In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to local inform... |
| CVE-2024-20070 | MEDIUM | 5.1 | 0.1% | Jun 3, 2024 | In modem, there is a possible information disclosure due to using risky cryptographic algorithm during connection establ... |
| CVE-2024-20069 | MEDIUM | 6.5 | 0.6% | Jun 3, 2024 | In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade che... |
| CVE-2024-20068 | MEDIUM | 5.9 | 0.6% | Jun 3, 2024 | In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service... |
| CVE-2024-20065 | MEDIUM | 4 | 0.1% | Jun 3, 2024 | In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf... |
| CVE-2024-36392 | MEDIUM | 6.1 | 0.3% | Jun 2, 2024 | MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2024-5587 | MEDIUM | 6.9 | 0.5% | Jun 2, 2024 | A vulnerability was found in Casdoor up to 1.335.0. It has been classified as problematic. Affected is an unknown functi... |
| CVE-2024-4344 | MEDIUM | 4.3 | 0.2% | Jun 2, 2024 | The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Cross-Sit... |
| CVE-2024-35647 | MEDIUM | 5.9 | 0.3% | Jun 2, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Global Noti... |
| CVE-2024-35646 | MEDIUM | 5.9 | 0.3% | Jun 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnens... |
| CVE-2024-35645 | MEDIUM | 5.9 | 0.3% | Jun 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar R... |
| CVE-2024-3200 | MEDIUM | 6.5 | 0.5% | Jun 1, 2024 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode ... |
| CVE-2024-35636 | MEDIUM | 4.3 | 0.2% | Jun 1, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Uploadcare Uploadcare File Uploader and Adaptive Delivery (beta) uplo... |
| CVE-2024-2295 | MEDIUM | 6.4 | 0.3% | Jun 1, 2024 | The Contact Form Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [xyz-cfm-for... |
| CVE-2024-2506 | MEDIUM | 6.4 | 0.3% | Jun 1, 2024 | The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to St... |
| CVE-2024-1324 | MEDIUM | 5.3 | 0.3% | Jun 1, 2024 | The QQWorld Auto Save Images plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabili... |
| CVE-2024-5501 | MEDIUM | 6.4 | 0.3% | Jun 1, 2024 | The Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2024-4342 | MEDIUM | 5.4 | 0.3% | Jun 1, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now